πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-43826 β€Ό

Envoy is an open source edge and service proxy, designed for cloud-native applications. In affected versions of Envoy a crash occurs when configured for :ref:`upstream tunneling <envoy_v3_api_field_extensions.filters.network.tcp_proxy.v3.TcpProxy.tunneling_config>` and the downstream connection disconnects while the the upstream connection or http/2 stream is still being established. There are no workarounds for this issue. Users are advised to upgrade.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-21655 β€Ό

Envoy is an open source edge and service proxy, designed for cloud-native applications. The envoy common router will segfault if an internal redirect selects a route configured with direct response or redirect actions. This will result in a denial of service. As a workaround turn off internal redirects if direct response entries are configured on the same listener.

πŸ“– Read

via "National Vulnerability Database".
πŸ“’ Novel phishing method deceives users with ubiquitous IT support tool πŸ“’

The man-in-the-middle attack can be used for a range of nefarious purposes, including credential theft and malicious code injection

πŸ“– Read

via "ITPro".
πŸ“’ Hackers caught dropping malware into Microsoft Teams chats πŸ“’

The self-administering files can take complete control of a user's system after a single click

πŸ“– Read

via "ITPro".
πŸ“’ Cisco patches bug that could break its email security service with a single message πŸ“’

A carefully crafted email could freeze Cisco's Email Security Appliance interface and stop it processing messages

πŸ“– Read

via "ITPro".
πŸ“’ UK, US officials say Russia was behind DDoS attacks against Ukraine πŸ“’

The Russian Embassy in the US slammed the accusations as "baseless statements"

πŸ“– Read

via "ITPro".
πŸ“’ Australian firms reported 464 data breaches in second half of 2021 πŸ“’

Malicious or criminal attacks remain the leading source of incidents, accounting for 55% of the total

πŸ“– Read

via "ITPro".
πŸ“’ Nokia debuts new SaaS services in security and analytics πŸ“’

The offerings accelerate time-to-value while focusing on analytics, security, and monetization

πŸ“– Read

via "ITPro".
πŸ“’ GitHub goes open source on security research πŸ“’

Community members, enthusiasts, researchers, and academics are now able to submit their own research to widen the understanding of security vulnerabilities

πŸ“– Read

via "ITPro".
πŸ“’ Ten ways to protect your company from the next big data breach πŸ“’

Even big-name corporations can’t prevent all breaches, but there are ways to protect your business

πŸ“– Read

via "ITPro".
πŸ“’ More than 80% of UK businesses paid ransomware demands in 2021 πŸ“’

The figure means UK organisations are twice as likely to pay a ransom demand compared to the global average

πŸ“– Read

via "ITPro".
πŸ“’ Only ever use black bars to redact text, warns security researcher πŸ“’

Researcher Dan Petro shows how pixelation can be easily reversed using algorithms

πŸ“– Read

via "ITPro".
πŸ“’ US pledges to take a 'hands-on' approach to disrupting cyber criminals πŸ“’

The country has promised 'proactivity' on cyber warfare as it launches new government cyber crime taskforces

πŸ“– Read

via "ITPro".
πŸ“’ Why AI and machine learning are vital cybersecurity tools for 2022 πŸ“’

Matt Aldridge, Principal Solutions Consultant at Carbonite + Webroot, explores how understanding of AI/ML is lagging behind

πŸ“– Read

via "ITPro".
πŸ“’ Adobe forced to patch its own failed security update πŸ“’

Company issues new fix for e-commerce vulnerability after researchers bypass the original update

πŸ“– Read

via "ITPro".
πŸ“’ GitHub launches code scanning tool for JavaScript and TypeScript projects πŸ“’

The experimental, machine learning-powered feature aims to identify security vulnerabilities using open source expertise

πŸ“– Read

via "ITPro".
πŸ“’ Microsoft releases analysis of Web3 'ice phishing' attack πŸ“’

New phishing method targets an immature technology stack on the next generation of the internet

πŸ“– Read

via "ITPro".
πŸ“’ NordPass teams up with insurance provider Cowbell Cyber to improve security awareness πŸ“’

Policy holders will be eligible for a 15% discount on NordPass Business

πŸ“– Read

via "ITPro".
β€Ό CVE-2022-0736 β€Ό

Insecure Temporary File in GitHub repository mlflow/mlflow prior to 1.23.1.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Google Groups unsubscribe feature abused to remove members without consent πŸ—“οΈ

β€˜This could have destroyed the Google Payment system flow,’ security researcher tells The Daily Swig

πŸ“– Read

via "The Daily Swig".
πŸ‘1
β€Ό CVE-2022-0724 β€Ό

Insecure Storage of Sensitive Information in GitHub repository microweber/microweber prior to 1.3.

πŸ“– Read

via "National Vulnerability Database".